cbcvebase.

Debian Linux vulnerabilities

9,954 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,954
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4153MEDIUM4310LOW358

Vulnerabilities

Page 190 of 498
CVE-2021-45469P3HIGHCVSS 7.8v9.0v10.0+1 more2021-12-23
CVE-2021-45469 [HIGH] CWE-125 CVE-2021-45469: In __f2fs_setxattr in fs/f2fs/xattr.c in the Linux kernel through 5.15.11, there is an out-of-bounds In __f2fs_setxattr in fs/f2fs/xattr.c in the Linux kernel through 5.15.11, there is an out-of-bounds memory access when an inode has an invalid last xattr entry.
nvd
CVE-2019-19728P3HIGHCVSS 7.5v10.02020-01-13
CVE-2019-19728 [HIGH] CWE-269 CVE-2019-19728: SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 executes srun --uid with incorrect privileges. SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 executes srun --uid with incorrect privileges.
nvd
CVE-2022-1652P3HIGHCVSS 7.8v10.02022-06-02
CVE-2022-1652 [HIGH] CWE-416 CVE-2022-1652: Linux Kernel could allow a local attacker to execute arbitrary code on the system, caused by a concu Linux Kernel could allow a local attacker to execute arbitrary code on the system, caused by a concurrency use-after-free flaw in the bad_flp_intr function. By executing a specially-crafted program, an attacker could exploit this vulnerability to execute arbitrary code or cause a denial of service condition on the system.
nvd
CVE-2024-27405P3HIGHCVSS 7.5v10.02024-05-17
CVE-2024-27405 [HIGH] CWE-476 CVE-2024-27405: In the Linux kernel, the following vulnerability has been resolved: usb: gadget: ncm: Avoid droppin In the Linux kernel, the following vulnerability has been resolved: usb: gadget: ncm: Avoid dropping datagrams of properly parsed NTBs It is observed sometimes when tethering is used over NCM with Windows 11 as host, at some instances, the gadget_giveback has one byte appended at the end of a proper NTB. When the NTB is parsed, unwrap call looks for
nvd
CVE-2018-10902P3HIGHCVSS 7.8v8.0v9.02018-08-21
CVE-2018-10902 [HIGH] CWE-416 CVE-2018-10902: It was found that the raw midi kernel driver does not protect against concurrent access which leads It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file. A malicious local attacker could possibly use this for privilege escalation.
nvd
CVE-2019-3467P3HIGHCVSS 7.8v8.0v9.0+1 more2019-12-23
CVE-2019-3467 [HIGH] CWE-732 CVE-2019-3467: Debian-edu-config all versions < 2.11.10, a set of configuration files used for Debian Edu, and debi Debian-edu-config all versions < 2.11.10, a set of configuration files used for Debian Edu, and debian-lan-config < 0.26, configured too permissive ACLs for the Kerberos admin server, which allowed password changes for other Kerberos user principals.
nvd
CVE-2018-8781P3HIGHCVSS 7.8v7.0v8.0+1 more2018-04-23
CVE-2018-8781 [HIGH] CWE-190 CVE-2018-8781: The udl_fb_mmap function in drivers/gpu/drm/udl/udl_fb.c at the Linux kernel version 3.4 and up to a The udl_fb_mmap function in drivers/gpu/drm/udl/udl_fb.c at the Linux kernel version 3.4 and up to and including 4.15 has an integer-overflow vulnerability allowing local users with access to the udldrmfb driver to obtain full read and write permissions on kernel physical pages, resulting in a code execution in kernel space.
nvd
CVE-2021-45417P3HIGHCVSS 7.8v9.0v10.0+1 more2022-01-20
CVE-2021-45417 [HIGH] CWE-787 CVE-2021-45417: AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as X AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS extended attributes or tmpfs ACLs), because of a heap-based buffer overflow.
nvd
CVE-2021-27803P3HIGHCVSS 7.5v9.0v10.02021-02-26
CVE-2021-27803 [HIGH] CVE-2021-27803: A vulnerability was discovered in how p2p/p2p_pd.c in wpa_supplicant before 2.10 processes P2P (Wi-F A vulnerability was discovered in how p2p/p2p_pd.c in wpa_supplicant before 2.10 processes P2P (Wi-Fi Direct) provision discovery requests. It could result in denial of service or other impact (potentially execution of arbitrary code), for an attacker within radio range.
nvd
CVE-2018-10853P3HIGHCVSS 7.8v8.02018-09-11
CVE-2018-10853 [HIGH] CWE-250 CVE-2018-10853: A flaw was found in the way Linux kernel KVM hypervisor before 4.18 emulated instructions such as sg A flaw was found in the way Linux kernel KVM hypervisor before 4.18 emulated instructions such as sgdt/sidt/fxsave/fxrstor. It did not check current privilege(CPL) level while emulating unprivileged instructions. An unprivileged guest user/process could use this flaw to potentially escalate privileges inside guest.
nvd
CVE-2017-6964P3HIGHCVSS 7.8v8.02017-03-28
CVE-2017-6964 [HIGH] CWE-252 CVE-2017-6964: dmcrypt-get-device, as shipped in the eject package of Debian and Ubuntu, does not check the return dmcrypt-get-device, as shipped in the eject package of Debian and Ubuntu, does not check the return value of the (1) setuid or (2) setgid function, which might cause dmcrypt-get-device to execute code, which was intended to run as an unprivileged user, as root. This affects eject through 2.1.5+deb1+cvs20081104-13.1 on Debian, eject before 2.1.5+deb1+cvs2
nvd
CVE-2013-4532P3HIGHCVSS 7.8v8.0v9.0+1 more2020-01-02
CVE-2013-4532 [HIGH] CWE-119 CVE-2013-4532: Qemu 1.1.2+dfsg to 2.1+dfsg suffers from a buffer overrun which could potentially result in arbitrar Qemu 1.1.2+dfsg to 2.1+dfsg suffers from a buffer overrun which could potentially result in arbitrary code execution on the host with the privileges of the QEMU process.
nvd
CVE-2021-33286P3HIGHCVSS 7.8v9.0v10.0+1 more2021-09-07
CVE-2021-33286 [HIGH] CWE-787 CVE-2021-33286: In NTFS-3G versions < 2021.8.22, when a specially crafted unicode string is supplied in an NTFS imag In NTFS-3G versions < 2021.8.22, when a specially crafted unicode string is supplied in an NTFS image a heap buffer overflow can occur and allow for code execution.
nvd
CVE-2022-41751P3HIGHCVSS 7.8v10.0v11.02022-10-17
CVE-2022-41751 [HIGH] CWE-78 CVE-2022-41751: Jhead 3.06.0.1 allows attackers to execute arbitrary OS commands by placing them in a JPEG filename Jhead 3.06.0.1 allows attackers to execute arbitrary OS commands by placing them in a JPEG filename and then using the regeneration -rgt50 option.
nvd
CVE-2023-3111P3HIGHCVSS 7.8v10.0v11.02023-06-05
CVE-2023-3111 [HIGH] CWE-416 CVE-2023-3111: A use after free vulnerability was found in prepare_to_relocate in fs/btrfs/relocation.c in btrfs in A use after free vulnerability was found in prepare_to_relocate in fs/btrfs/relocation.c in btrfs in the Linux Kernel. This possible flaw can be triggered by calling btrfs_ioctl_balance() before calling btrfs_ioctl_defrag().
nvd
CVE-2022-30789P3HIGHCVSS 7.8v9.0v10.0+1 more2022-05-26
CVE-2022-30789 [HIGH] CWE-787 CVE-2022-30789: A crafted NTFS image can cause a heap-based buffer overflow in ntfs_check_log_client_array in NTFS-3 A crafted NTFS image can cause a heap-based buffer overflow in ntfs_check_log_client_array in NTFS-3G through 2021.8.22.
nvd
CVE-2022-30786P3HIGHCVSS 7.8v9.0v10.0+1 more2022-05-26
CVE-2022-30786 [HIGH] CWE-787 CVE-2022-30786: A crafted NTFS image can cause a heap-based buffer overflow in ntfs_names_full_collate in NTFS-3G th A crafted NTFS image can cause a heap-based buffer overflow in ntfs_names_full_collate in NTFS-3G through 2021.8.22.
nvd
CVE-2022-30788P3HIGHCVSS 7.8v9.0v10.0+1 more2022-05-26
CVE-2022-30788 [HIGH] CWE-787 CVE-2022-30788: A crafted NTFS image can cause a heap-based buffer overflow in ntfs_mft_rec_alloc in NTFS-3G through A crafted NTFS image can cause a heap-based buffer overflow in ntfs_mft_rec_alloc in NTFS-3G through 2021.8.22.
nvd
CVE-2017-15868P3HIGHCVSS 7.8v8.02017-12-05
CVE-2017-15868 [HIGH] CWE-20 CVE-2017-15868: The bnep_add_connection function in net/bluetooth/bnep/core.c in the Linux kernel before 3.19 does n The bnep_add_connection function in net/bluetooth/bnep/core.c in the Linux kernel before 3.19 does not ensure that an l2cap socket is available, which allows local users to gain privileges via a crafted application.
nvd
CVE-2017-3136P3MEDIUMCVSS 5.9v8.02019-01-16
CVE-2017-3136 [MEDIUM] CWE-617 CVE-2017-3136: A query with a specific set of characteristics could cause a server using DNS64 to encounter an asse A query with a specific set of characteristics could cause a server using DNS64 to encounter an assertion failure and terminate. An attacker could deliberately construct a query, enabling denial-of-service against a server if it was configured to use the DNS64 feature and other preconditions were met. Affects BIND 9.8.0 -> 9.8.8-P1, 9.9.0 -> 9.9.9-P6,
nvd
Debian Linux vulnerabilities | cvebase